Back to overview

CVE-2026-9577

Description
The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?page=post-status-notifier-lite`), leading to a Reflected Cross-Site Scripting vulnerability that fires in the administrator's session when they are tricked into following a crafted URL.

Metadata

CVE ID
CVE-2026-9577
State
PUBLISHED
Assigner
WPScan
Reserved
2026-05-26 12:45 UTC
Published
2026-07-23 06:00 UTC
Last updated
2026-07-23 06:00 UTC
Vendor / Product
Unknown / Post Status Notifier Lite
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Unknown Post Status Notifier Lite 0 < 1.13.0
Weakness (CWE)
CWESourceDescription
cna CWE-79 Cross-Site Scripting (XSS)
Back to overview